vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.6 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=194)
-   -   Miscellaneous Hacks - Check Proxy RBL on New User Registration. (https://vborg.vbsupport.ru/showthread.php?t=131852)

smoknz28 12-18-2006 09:22 PM

Installed....thanks for sharing this code with us. :up:

DaNIEL MeNTED 12-18-2006 11:04 PM

Quote:

Originally Posted by sinisterpain (Post 1141170)
Sorry I edited my post above, to say it did work any thank you for this great mod.

Ha! No problem... thanks for letting me know its working for you.

Quote:

Originally Posted by smoknz28 (Post 1141211)
Installed....thanks for sharing this code with us. :up:

My pleasure. Anything to keep the trolls at bay...


Incidentally, I recommend checking out www.ahbl.org - they seem to have resolved the issues they were having with their site and from my tests on dnsstuff.com with various google'd lists of proxy servers they have ALL the ones I tested listed...

I've setup my production server to use ahbl.org and assuming I get no false positives between now and the next update (what? no new requests for features?) then I may make that the default rather than spamhaus.org which is less targetted to web proxies.

sinisterpain 12-18-2006 11:39 PM

Quote:

Originally Posted by DaNIEL MeNTED (Post 1141275)
Ha! No problem... thanks for letting me know its working for you.



My pleasure. Anything to keep the trolls at bay...


Incidentally, I recommend checking out www.ahbl.org - they seem to have resolved the issues they were having with their site and from my tests on dnsstuff.com with various google'd lists of proxy servers they have ALL the ones I tested listed...

I've setup my production server to use ahbl.org and assuming I get no false positives between now and the next update (what? no new requests for features?) then I may make that the default rather than spamhaus.org which is less targetted to web proxies.

Can you not use both?

DaNIEL MeNTED 12-18-2006 11:51 PM

Quote:

Originally Posted by sinisterpain (Post 1141298)
Can you not use both?

For sure... I've put it first for testing.

sinisterpain 12-19-2006 12:22 AM

Quote:

Originally Posted by DaNIEL MeNTED (Post 1141307)
For sure... I've put it first for testing.

Are you using this addy for check dnsbl.ahbl.org

DaNIEL MeNTED 12-19-2006 01:12 PM

Quote:

Originally Posted by sinisterpain (Post 1141326)
Are you using this addy for check dnsbl.ahbl.org

Yes..

My list is as follows:

sbl-xbl.spamhaus.org
proxies.dnsbl.sorbs.net
dnsbl.ahbl.org

Originally I had ahbl.org at the top - since the RBL Checker stops after a positive match I've moved it to the bottom. This way when I see a report with ahbl.org I know the IP was missed by spamhaus.org and sorbs.net.

If anyone else is willing to setup their forum the same way and report back on whether or not spamhaus, sorbs, or ahbl does the majority of the blocking it will help me decide on a default for the next release.

I don't really want to do too many checks... so I'd like to have 1-2 RBLs as the default.

falter 12-19-2006 01:29 PM

Guys, I'd recommend against using dnsbl.ahbl.org or sbl-xbl.spamhaus.org. Their primary function is to provide a list of Open Mail Relays and email spamming sources, which are an ENTIRE different world than Open Proxies. I don't think that fact is illustrated enough in this thread.

AHBL is particularly aggressive in that they are willing to list blocks of ip addresses. That is, if you have users on a Seattle Area DSL network, and an open mail relay shows up on their network, both that mail relay and your users (or potential users) will be blocked by AHBL.

You guys really need to read and understand the purpose and the usage of these blacklists before slapping them in. Many of these blocklists prohibit the usage of their services in this way. You're unnecessarily hitting services that have finite resources. Don't be so eager to block IPs willy nilly and think you're making a difference. You're not. If your goal is to block users coming through anonymizers, proxies, or even the TOR network, then use blacklists whose function is to only report anonymizers, proxies, and TOR networks. The fact of the matter is that you're not going to see a lot of hits with a blacklist like this simply because not many people are going to register with your site who are actually using proxies.

Here's what I'm using currently:
proxies.dnsbl.sorbs.net
tor.ahbl.org

I don't get many hits, but that's because I don't expect many hits (that's the reality of things).

Again, I like this add-on, I think it's very useful. I'm not criticizing it's usage. All I'm trying to do is help people understand what they're doing a little bit better.

DementedMindz 12-19-2006 06:28 PM

Quote:

Originally Posted by falter (Post 1141581)
If your goal is to block users coming through anonymizers, proxies, or even the TOR network, then use blacklists whose function is to only report anonymizers, proxies, and TOR networks.

ok so would what you listed stop all of these? im mostly looking to block anonymizers this way they can not connect and make a user name with a anonymous proxie

proxies.dnsbl.sorbs.net
tor.ahbl.org

falter 12-19-2006 06:39 PM

Quote:

Originally Posted by DementedMindz (Post 1141757)
ok so would what you listed stop all of these? im mostly looking to block anonymizers this way they can not connect and make a user name with a anonymous proxie

proxies.dnsbl.sorbs.net
tor.ahbl.org

You're never going to stop ALL proxies in the world. You can only stop those that have been reported or found. However, my list will ONLY block proxies, and will not false-positive by blocking legitimate hosts who happen to match up with spammy networks, etc.

Now, If this add-on had the ability to interpret the response from various blacklists, you could get more coverage. For example, spamhaus will return indicators as to why a particular IP has matched in their database, and these indicators might include an option saying that it is an open proxy. However, this interpretation doesn't occur, so you will end up matching ips against things like Dial up networks, dynamic ip hosts, and ip netblocks that *might* include spammers.

DementedMindz, and anyone else, if it is your intention to block just Open Proxies, then use the following two hosts, as I do:

proxies.dnsbl.sorbs.net
tor.ahbl.org

DementedMindz 12-19-2006 06:42 PM

yeah im looking at opm.tornevall.org now as they have a few on there too im reading about it here http://opm.tornevall.org/ cause say you go to http://anonymouse.org you can get right by all these things.


All times are GMT. The time now is 11:31 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01339 seconds
  • Memory Usage 1,751KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (8)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete